This report package contains a merged root-cause analysis of multiple VyOS privilege-boundary vulnerabilities found during an authorized audit.
The uploaded archive is organized under security-reports/merged/. Each root-cause folder contains a SUMMARY.md and DETAIL.md. The DETAIL.md files list the
affected commands, GraphQL operations, local binaries, sockets, or generated files, and include one complete end-to-end PoC example with setup, trigger,
verification, and cleanup steps.
The main impact classes are:
1. Low-privilege GraphQL token users can reach op-mode handlers without equivalent CLI/operator authorization checks. Several handlers then pass attacker-
controlled values into root shell command strings, resulting in root command execution.
2. The shared interface_exists() helper validates interface names by checking os.path.exists('/sys/class/net/{interface}'). Path traversal can satisfy this guard
with attacker-created /tmp files, after which the original interface string reaches root shell command sinks.
3. Management API keys or key-bearing runtime/config state are exposed to lower-privileged users through local files, generated config caches, cli-shell-api
output, or GraphQL-accessible paths. Recovered keys can provide full management API access and root command execution through supported configuration workflows.
4. Several generated secret files and runtime artifacts are world-readable, exposing VPN, TACACS, stunnel, Zabbix, API, and archived configuration secrets to
local low-privilege users.
5. World-writable IPC or include paths allow local low-privilege users to influence privileged services such as configd, hostsd/PowerDNS, and zabbix-agent.
6. Over-broad Linux file capabilities and sudoers rules expose privileged network, system, packet capture, and root command execution capabilities to local low-
privilege or operator users.
7. nginx error-log handling preserves attacker-controlled CRLF or terminal control characters, enabling unauthenticated log trust-boundary injection.
The reports distinguish authenticated, local, operator, and unauthenticated attack models. They also distinguish direct root command execution, service-account
command execution, sensitive-read disclosure, and non-RCE privilege-boundary impacts. Individual DETAIL.md files should be treated as the authoritative
reproduction and remediation notes for each root cause.{F116477488}